HYPERSCRAPE Malware
Summary
As for HYPERSCRAPE, it is a threat written in .NET for Windows PCs and its primary goal is to collect information from the victims Gmail, Yahoo! To perform its threatening functions, HYPERSCRAPE requires the login credentials for the specific account to have already been compromised and obtained by the threat actors. Once it has managed to successfully access the victims account, the threats first action is to check the current language and switch it to English, if necessary. When its current run is finished, the threat makes an HTTP POST request to its Command-and-Control (C2, C&C) server, transmitting status and system information but not the downloaded emails. After all, earlier versions of the threat were able to request data from Google Takeout, but the hackers removed this functionality for unknown reasons.